Перейти к содержимому
Noroxi

Записи apostrophecms

17 опубликованных записей вендора apostrophecms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
100 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

17 записей
  • CVE-2021-25979
    39Наблюдать

    Apostrophe - Insufficient Session Expiration

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apostrophecms · apostrophecms8 нояб. 2021 г.

  • CVE-2026-32731
    39Наблюдать

    ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

    КритическаяCVSS 9,9Proof of conceptEPSS 1 %

    apostrophecms · import-export18 мар. 2026 г.

  • CVE-2026-35569
    34Наблюдать

    ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    apostrophecms · apostrophecms15 апр. 2026 г.

  • CVE-2026-32730
    32Наблюдать

    ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    apostrophecms · apostrophecms18 мар. 2026 г.

  • CVE-2022-25887
    30Наблюдать

    Regular Expression Denial of Service (ReDoS)

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    apostrophecms · sanitize-html30 авг. 2022 г.

  • CVE-2016-1000237
    24Наблюдать

    sanitize-html before 1.4.3 has XSS.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    apostrophecms · sanitize-html23 янв. 2020 г.

  • CVE-2026-40186
    24Наблюдать

    ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    apostrophecms · apostrophecms15 апр. 2026 г.

  • CVE-2014-125128
    24Наблюдать

    'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    apostrophecms · sanitize-html8 сент. 2025 г.

  • CVE-2019-25225
    24Наблюдать

    `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    apostrophecms · sanitize-html8 сент. 2025 г.

  • CVE-2021-26539
    22Наблюдать

    Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacke

    СредняяCVSS 5,3Эксплойта нетEPSS 2 %

    apostrophecms · sanitize-html8 февр. 2021 г.

  • CVE-2021-26540
    22Наблюдать

    Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when

    СредняяCVSS 5,3Эксплойта нетEPSS 2 %

    apostrophecms · sanitize-html8 февр. 2021 г.

  • CVE-2024-21501
    21Наблюдать

    Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attri

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    apostrophecms · sanitize-html24 февр. 2024 г.

  • CVE-2026-33888
    21Наблюдать

    ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    apostrophecms · apostrophecms15 апр. 2026 г.

  • CVE-2021-25978
    21Наблюдать

    Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Jav

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    apostrophecms · apostrophecms7 нояб. 2021 г.

  • CVE-2026-39857
    21Наблюдать

    Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    apostrophecms · apostrophecms15 апр. 2026 г.

  • CVE-2026-33889
    21Наблюдать

    ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    apostrophecms · apostrophecms15 апр. 2026 г.

  • CVE-2026-33877
    14Наблюдать

    ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

    НизкаяCVSS 3,7Эксплойта нетEPSS 0 %

    apostrophecms · apostrophecms15 апр. 2026 г.